PT-2026-96735 · Misp · Misp

·

CVE-2026-95679

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MISP (affected versions not specified)
Description The RequestHandlerComponent automatically decodes XML request bodies on all write requests. A logic error exists in the Xml::build() library within its readFile guard condition due to PHP operator precedence, which allows the HTTPS branch to bypass the readFile check. Consequently, a request body containing a bare HTTPS URL is treated as a locator and fetched by the server. Since the /cspReport endpoint accepts XML content types and is unauthenticated, a remote attacker can send a POST request with a crafted XML body to force the server to issue outbound HTTPS requests to arbitrary targets. This can be used to probe internal services, trigger actions on internal HTTPS endpoints, or perform timing-based reconnaissance of the network environment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95679

Affected Products

Misp